All Apps and Add-ons

Salesforce Reports not Indexing correctly

New Member

Hi,

I'm trying to index Salesforce Reports using this app, I've configured my account / token / password.

Here is what I see in my index:

alt text

I do not see any errors in the internal log while authenticating or consulting the report:

alt text

I'm not sure how to fix this or workaround to get my reports to Splunk (I rather not to download + upload or monitor).

Thanks a lot for your help!

JP

0 Karma

New Member

Hi There

I too am having the same problem. I am using https://na6.salesforce.com/[reportid] as the url.

alt text

When I go and click extract additional fields, it comes up with;

alt text

0 Karma

New Member

Hi @gschrank

I had the same problem where the report access was successful but the data ingested was all blank. The issue here is with the permission associated with the user which is used to interface splunk and salesforce. Ensure this user has System Admin Profile and check if you are not only able to access the report via the GUI but also to download the same. Mere accessing the report wont do.

Let me know if this helps.

0 Karma

New Member

Hi

I'm closing this question as the error as I needed to configure the account to the classic SalesForce view (not the summer '18); when the script was trying to export the data the report id I was using had some extra characters and the export had an option to export with format.

After I returned to the classic view and used the report id without the extra characters I was able to correctly index the report.

JP

0 Karma

New Member

Hi

I have exaclty the same problem but not sure how did you fix it. Could you explain me the steps?....because i have classic view ans still having the issue.

0 Karma

New Member

Hi, jbelloso, verify which type of URL you are using to configure the Salesforce SOQL, it needs to bemy.salesforce.com/XXXX rather than lightning/r/Report/XXXXXX as the last one add extra information that will not allow the query to run as expected.

If this doesn't help, please post the internal logs and the output of the index query.

0 Karma

SplunkTrust
SplunkTrust

How did you onboard these logs? Did you use the SalesForce TA? You don't have correct base configs which is why its not linebreaking correctly

0 Karma

New Member

I'm using the Salesforce Reports TA splunkbase /app/3567/

The App just request account, token and password -> I created an input with the Salesforce Report ID.

I cant upload the current options as "Answers" won't allow me.

I'm not trying to integrate the Splunk App with the Add on to monitor the Reports Access (Via Object), so, as the Add-On do not give me the option to select the Report ID

JP

0 Karma

New Member

in the report id input - provide the entire URL(classic) to access the report. https://abcd.salesforce.com/{Report_Id}

This worked for me

0 Karma

SplunkTrust
SplunkTrust

What's happening is, the TA is thinking the null values are in json format so its creating a new event for each null event. Can you confirm your other events are correctly linebreaking?

0 Karma

New Member

Here is the props.conf

[salesforce:api:report]
ANNOTATE_PUNCT = 1
AUTO_KV_JSON = 1
BREAK_ONLY_BEFORE = None
BREAK_ONLY_BEFORE_DATE = 1
HEADER_MODE = None
KV_MODE = json
LEARN_MODEL = 1
LEARN_SOURCETYPE = 1
MUST_BREAK_AFTER = None
MUST_NOT_BREAK_AFTER = None
MUST_NOT_BREAK_BEFORE = None
SHOULD_LINEMERGE = 0
TRANSFORMS = None
category = REST API
detect_trailing_nulls = 0
disabled = 0
priority = None
pulldown_type = 1
sourcetype = None

0 Karma